![]() |
|
#1
|
||||
|
||||
|
The original inspiring thread by Rmus is here.
http://www.wilderssecurity.com/showthread.php?t=230837 It,s a very clever piece of malware, uses an aurorun.inf file and a dll( hidden as a vmx file) to do its dirty tricks and spreads via USB sticks. CFP - on default interactive security mode, you will get only one pop up that is execution of dll/ vmx file by rundll32. If u allow it, no more pop ups and malware is free to do all its actions. CFP however did label it as suspicious via file heuristics. EQS - seems similat to CFP though I tested it in hurry. PASS GesWall - you need to make a rule to isolate ur USB drive in GW( see the pic). It stopped the worm dead. TF - Fail, totally blind. Come on. Try ur HIPS once again. BTW - more pics are here but u need extremely tight rules to get many( though not all) of these pop ups and such rules are practically not feasible at all. http://rapidshare.com/files/186335754/pics.zip
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
Last edited by aigle : January 20th, 2009 at 04:42 AM. |
|
#2
|
||||
|
||||
|
Someone test it with SandboxIE
![]()
__________________
TuX Factory |
|
#3
|
||||
|
||||
|
Curious about DS as well since it monitors flash drives as they are plugged in.
Last edited by ThunderZ : January 20th, 2009 at 07:53 AM. |
|
#4
|
||||
|
||||
|
What about the Prevx Edge discussion of their success at http://www.prevx.com/blog.asp ? Is HIPS simply the wrong tool for some of the modern malware?
__________________
Windows 7 x64 HP/Vista Ultimate x32-SP2-UAC off/, Opera 10.6, OA++ latest beta, Avast! 5.0 latest beta Pro/Free, Prevx 3.0.5/SafeOnline latest beta, MVPS Hosts, Windows Defender, SAS/MBAM offline, Reflect/ True Image just in case
Last edited by sded : January 19th, 2009 at 10:00 PM. |
|
#5
|
||||
|
||||
|
And what about Online Armor, another current modern HIPS?
__________________
Windows 7 x64 HP/Vista Ultimate x32-SP2-UAC off/, Opera 10.6, OA++ latest beta, Avast! 5.0 latest beta Pro/Free, Prevx 3.0.5/SafeOnline latest beta, MVPS Hosts, Windows Defender, SAS/MBAM offline, Reflect/ True Image just in case
|
|
#6
|
||||
|
||||
|
Sample files I picked up.
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
|
|
#7
|
|||
|
|||
|
Quote:
Aigle I can make a pass custom rule in ThreatFire, like you did with GeSWall So either you consider GeSWall a FAIL or you reward ThreatFire with a PASS Aigle do you have two USB sticks and two or more USB ports? Would you mind testing GeSWall with the custom rule you applied for USB stick (harddisk1) with the virus on teh second USB stick. I bet GeSWall will fail miserably ![]() Come on man, use one stick to measure results ![]() Last edited by Kees1958 : January 20th, 2009 at 04:36 AM. |
|
#8
|
||||
|
||||
|
Comodo Defense+
It's often the problem with "classical" HIPS: the user has to deccide himself what to allow or block. |
|
#9
|
|||
|
|||
|
Quote:
If somebody provides a dropper, I can report the results. |
|
#10
|
||||
|
||||
|
Caution: Please don't post links. They will certainly be removed.
Pete |
|
#11
|
||||
|
||||
|
Quote:
As far as GW is concerned, it,s lacking the feature to protect USB sticks by default. I just added it manually. Development of GW is stalled ofcourse. Basic functionality is there but u need to implement it somehow. I used this rule in GW as there seemed no other way for me to run this malware isolated. It,s not a PASS infact I agree unless u tweak GW as it lacks protection of USB sticks by default. Quote:
![]()
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
Last edited by aigle : January 20th, 2009 at 06:20 AM. |
|
#12
|
|||
|
|||
|
Quote:
The ability to apply minor nuances marks a great mind. You are a sport Last edited by Kees1958 : January 20th, 2009 at 05:47 AM. |
|
#13
|
||||
|
||||
|
Will test SandboxIE later when I'm at home, but I have no doubt it will pass, with the USB drive forced to run sandboxed.
__________________
I ♥ SandboxIE
|
|
#14
|
|||
|
|||
|
Quote:
Your faith in the wondrous SandboxIE is well placed,I'm certain it'll pass,but await your findings in any case. ![]() Has anyone tried this with Mamutu yet? |
|
#15
|
|||
|
|||
|
Quote:
Guys, again in regard to Sandboxie - let's make a special configuration rule (force USB drive run sandboxed) - ghee it passes a real malware sample What in regard to XP: - I have a SRP rule blocking executables from running in RECYCLER - Ghee my windows XP passes in Limited User Account, what a great HIPS old XP is, it passes! When you disagree with the second observation, why do you agree with the first observation? There is something I seem to misunderstand completely , so better keep my mouth shut ![]() Last edited by Kees1958 : January 20th, 2009 at 08:07 AM. |
|
#16
|
||||
|
||||
|
Quote:
Actually Kees, I don't disagree with your 2nd observation. SandboxIE with it's default config would not protect from this. A default XP is vulnerable. I think some classic HIPS could be vulnerable too. But when you design your setup to cover infection vectors, you only see PASSES. It doesn't matter if it's a HIPS, a sandbox, LUA, or other method. The important thing is to have the defenses well planned. For what it's worth, If I had XP Pro, and could use SRP, I probably wouldn't use Sandboxie, but I'm stuck with XP Home...
__________________
I ♥ SandboxIE
|
|
#17
|
||||
|
||||
|
Nice test, what about OA or DefenseWall?
__________________
Windows 7 x32 Look 'n' Stop v2.07 & DefenseWall v3 ~ |
|
#18
|
|||
|
|||
|
According to the PC Tools Forum the new Threatfire Beta will detect the conficker worm.
regards, Joerg |
|
#19
|
||||
|
||||
|
a)to be honest,any classical HIPS should give you at least 1 execution warning...soooo if you just pop the thumb drive in and you get a prompt,ya you deserve to be infected
![]() b) @ aigle i don't know why you say that it needs very deep rules (in CPF) to get the right warning..anyone that uses cpf adds those and paranoid mode has them on by default http://www.imageshack.gr/files/kccat7zu2wqzdfzed5ze.jpg
__________________
"Two things are infinite: the universe and human stupidity; and I'm not sure about the universe" |
|
#20
|
|||
|
|||
|
Reports of Eset v 3.0.669.0
Edit: Sorry if my post is off topic don't know much abt HIPS
__________________
My Very First Blog ![]() Malware Defender Last edited by icr : January 20th, 2009 at 12:11 PM. |
|
#21
|
|||
|
|||
|
OA is much the same to the others. There was execution alert about jwgkvsq.vmx wanting to run. Once allowed computer is infected.
|
|
#22
|
||||
|
||||
|
Quote:
__________________
PE Guard 2.1/HitMan Pro/WinPatrol Plus/ProcessGuard 3.5 |
|
#23
|
|||
|
|||
|
Quote:
Hey, what about the case of 2+ HDDs? ![]() It would be pretty good if there was a way to add rule for removable drives automatically, without putting the user through the misery of doing the computation on total number of HDDs & USB sticks by hand ![]() |
|
#24
|
||||
|
||||
|
Quote:
![]() then why buy it at all?thats why you use it anyway,to copy stuff ![]() *hint* if LUA passes the sample then OA with checked the option "run unknown apps as untrusted" passes it too. duh! some1 pm me the sample please? ![]()
__________________
"Two things are infinite: the universe and human stupidity; and I'm not sure about the universe" |
|
#25
|
||||
|
||||
|
Quote:
![]() note:not tested yet on my part ![]()
__________________
PE Guard 2.1/HitMan Pro/WinPatrol Plus/ProcessGuard 3.5 |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|